Effective 21 August 2026
What GuroOS does with your account, your teaching work and your learners’ records — and, in particular, what it does and does not send to an AI provider.
GuroOS is a personal teaching workspace for individual teachers. This notice explains what the service does with information you put into it, what it sends elsewhere, and what you can do about either.
It is written for the Philippine Data Privacy Act of 2012 (RA 10173) and its implementing rules. Where the Act uses the words: you are the data subject for your own account information; for the learner records you keep here, your school is ordinarily the personal information controller and GuroOS processes those records on your instruction.
The operator’s registered name, address and Data Protection Officer must appear here before this notice is published. They are not filled in yet.
Four kinds of information, and they are treated differently:
This is the part worth reading closely, because it is where a teaching product most easily does something a teacher would not expect.
Learner names are replaced before anything reaches an AI provider. When a message, document or brief is sent for the assistant to work on, every learner from your own class lists who is named in it is substituted with a stable label — [Learner 1], [Learner 2] — and the names are put back in the reply before you read it. The provider sees the label, not the child.
A photograph cannot be de-identified, so it is gated instead. There is nothing textual in an image for the substitution to work on. Images are sent to a provider only where the operator has switched that on; where it is off, the assistant is told plainly that it cannot see the picture rather than being left to describe one it never received, and the attachment is labelled “Not sent to the assistant” in your workspace.
The assistant’s lookup tools return counts, never identities. When the assistant checks attendance or a gradebook mid-answer, what comes back is averages, tallies and your own labels for a class. No query behind those tools selects a learner’s name or an individual score.
Nothing generated is applied to your records on its own. Everything the assistant produces arrives as a draft with your review required before it is saved or used in class.
Your teaching content is not used to train anyone’s AI model, is not sold, and is not shared with other teachers, your school, or anybody else unless you export it and share it yourself.
A short list, and every entry is there because a feature needs it. Each receives only what that feature requires.
Some of these process data outside the Philippines. Where that happens the operator is responsible for the safeguards the Act requires of a cross-border transfer.
The Act gives you rights over your own information. Here is what each one means in this product.
Passwords are stored as Argon2 digests and never in a form anyone can read back. Sessions are server-side and can be revoked. Files are held under a per-teacher prefix so that erasing an account erases its objects with it. Every write to a learner’s record is recorded in the audit trail.
No system is beyond compromise. If a breach affects your information, the operator will notify you and the National Privacy Commission within the period the Act requires.
GuroOS is for teachers, and accounts are for adults. Learners do not sign in and have no account. Their records are here because you keep them here, in the same way a paper class record holds them — which is why the AI rules above are written the way they are.
When this notice changes materially, the effective date at the top changes with it and account holders are told by email before it takes effect.
Questions about this document: privacy@guro-os.com. Questions about using GuroOS: the support page.